Junglewise Threat Intelligence

CVE-2026-30080: OpenAirInterface AMF integrity protection bypass in Security Mode Control

CVE-2026-30080 · Severity: high · CVSS 7.5 · Published 2026-04-08

Executive brief

OpenAirInterface, an open-source implementation of 5G core network components, contains a security flaw in its Access and Mobility Management Function (AMF). The system incorrectly accepts connection requests that lack mandatory security protections, even when configured to require them. This allows an attacker to bypass integrity checks, potentially leading to the interception or replaying of mobile network signaling, which can compromise the reliability of the cellular connection.

Technical details

A vulnerability in OpenAirInterface (OAI) v2.2.0 AMF allows a security context downgrade during the initial registration procedure. Although the AMF may be configured to support NIA1 and NIA2 integrity algorithms, it incorrectly accepts a 'Security Mode Complete' message without integrity protection if a User Equipment (UE) claims to only support the IA0 (null integrity) algorithm. This occurs because the AMF proceeds with the registration instead of rejecting the UE's capability as per 3GPP specifications. An attacker can exploit this to bypass integrity checks and perform replay attacks on NAS (Non-Access Stratum) signaling. The issue is tracked in the OAI GitLab repository as issue #78.

Affected products

  • OpenAirInterface oai-cn5g-amf 2.2.0

Timeline

  • 2026-04-08: advisory: Initial disclosure of CVE-2026-30080

References

Related threats